[PATCH] RISC-V: KVM: Fix out-of-bounds by 1
Ethan Tidmore
ethantidmore06 at gmail.com
Wed Mar 18 14:19:22 PDT 2026
On Sat Feb 28, 2026 at 9:22 AM CST, Ethan Tidmore wrote:
> The array kvpmu->pmc is defined as:
>
> struct kvm_pmc pmc[RISCV_KVM_MAX_COUNTERS];
>
> So, accessing it with index RISCV_KVM_MAX_COUNTERS would be
> out-of-bounds by 1.
>
> Change index check from > to >=.
>
> Detected by Smatch:
> arch/riscv/kvm/vcpu_pmu.c:528 kvm_riscv_vcpu_pmu_ctr_info() error:
> buffer overflow 'kvpmu->pmc' 64 <= 64
>
> Fixes: 8f0153ecd3bf1 ("RISC-V: KVM: Add skeleton support for perf")
> Signed-off-by: Ethan Tidmore <ethantidmore06 at gmail.com>
> ---
Friendly ping.
Thanks,
ET
More information about the linux-riscv
mailing list